Daniel Trivellato, vice president of operational technology, healthcare and cyber risk solutions at Forescout, writes that cyber resilience is clinical resilience.
In healthcare, digital resilience and patient care are now so intertwined that disruptions in one directly impact the other. Every connected device, electronic health record and clinical system plays a role in delivering treatment. When those systems or the connections between them fail, whether through technical failure or cyberattack, the consequences are measured not just in downtime, but in delayed diagnoses, cancelled procedures and adverse patient outcomes. Therefore, we need to stop talking about cybersecurity as though it sits alongside healthcare. It now sits at its heart.
In today’s healthcare environment, cyber resilience is clinical resilience.
A successful cyberattack can compromise more than data or back-office systems, it can postpone surgery, divert ambulances, interrupt treatment and prevent clinicians from accessing the information they need to make life-saving decisions. Take the ransomware attack against pathology provider Synnovis, for example. It crippled blood testing services across south-east London, affecting Guy’s and St Thomas’, King’s College Hospital and several other NHS Trusts. Without access to pathology systems, hospitals had to postpone operations, delay outpatient appointments and switch to emergency blood transfusion procedures, even contributing to a national shortage of O-type blood. Ultimately, more than 11,000 outpatient appointments and elective procedures were delayed before services were fully restored.
Healthcare is a target for cybercriminals
Healthcare has long been an attractive target for cybercriminals. Patient records remain highly valuable, while hospitals often experience intense pressure to restore services quickly following an attack. Connected care, remote monitoring and expanding digital supply chains have only widened the opportunities available to attackers. Forescout’s own research highlights how healthcare has climbed the rankings of the world’s most targeted sectors, driven by a growing attack surface, valuable patient data and limited cybersecurity budgets and staffing across many healthcare delivery organisations.
The challenge is becoming even greater because the rules of cyber conflict are changing. While artificial intelligence is giving defenders powerful new tools to identify risk, automate investigations and respond faster than ever before, it unfortunately is doing the same for attackers.
Emerging frontier AI models, like Claude Mythos, can discover previously unknown software vulnerabilities at machine speed and mark a significant change in cybersecurity. Researchers have already demonstrated that these AI models can identify flaws that have remained hidden for years while dramatically reducing the time needed to build working exploits. What once took highly skilled researchers weeks or months can now happen in hours. In the hands of malicious actors, those same capabilities mean that cyberattacks can now unfold faster than human teams can respond.
For healthcare organisations, that acceleration in attack speed matters arguably more than almost any other sector. Hospitals are among the most technologically diverse environments in existence. Alongside traditional IT systems sit thousands of connected medical devices, imaging systems, laboratory equipment, pharmacy systems, building management controllers and internet-connected clinical technologies. Many were designed to operate for decades, not to withstand today’s rapidly evolving cyber threats.

Unique operational dilemma
Healthcare organisations also face a unique operational dilemma. Unlike most industries, they cannot simply take critical systems offline when new vulnerabilities are identified and need to be patched. Medical devices often require extensive validation before software can be updated, while life-sustaining equipment may need to remain operational around the clock. Even when security teams know where vulnerabilities exist, remediation is rarely straightforward.
Security teams have traditionally relied on having time to identify a vulnerability, understand its impact, prioritise remediation and deploy mitigations before attackers could take advantage. AI compresses that entire process. The shrinking period between discovery and exploitation leaves organisations with far less time and room for error. In practice, healthcare organisations simply cannot patch every vulnerability at the speed modern threats evolve.
The imperative, then, is not prevention alone, but reducing the exposure, limiting the blast radius and containing the threat before it reaches critical systems. To achieve this, security teams cannot rely on periodic security assessments or annual compliance exercises alone. They need continuous visibility into connected assets, communication and access pathways, and automated response to emerging risks and threats.
Visibility needs to extend beyond IT systems into medical, IoT and operational technology assets, forming the foundation of cyber resilience. Healthcare organisations cannot effectively protect critical systems, control access or isolate risky devices without first understanding the full scope of their environment.
Healthcare organisations also cannot protect devices and access pathways they do not know exist. They need visibility into what is connected, where it is located, who owns it, and who it communicates with. Understanding which systems directly affect patient care is essential to prioritise vulnerabilities and risk effectively, and having a complete picture of how clinical, operational and administrative systems connect to one another is crucial to respond quickly to threats.
Building resilience through automation
Finally, in an era where AI can accelerate attacks beyond human response times, automation is what allows defenders to keep pace. Applying smart automation to segmentation, secure remote access, and network access control, healthcare organisations can act on known risks faster and contain threats before they spread into clinical and operational environments. Segmentation and network access control are especially important in healthcare. When medical devices cannot be protected with security agents, quickly patched or taken offline without disrupting care, segmentation and network access control reduce exposure and contain compromise. They help create that control point, limiting which systems can communicate, which pathways can be used and how far an attack can spread.
Ultimately, healthcare leaders should not view cybersecurity as a technology investment competing with patient care budgets. It is now part of patient care itself. The security of every connected infusion pump, imaging device, clinical workstation and hospital network contributes to the delivery of safe, effective treatment. If those systems become unavailable, patient outcomes inevitably suffer.
The measure of healthcare innovation will not only be how quickly organisations adopt new technology, but how well they protect the digital foundations of care and, by doing so, the patients who depend on them.



